SB2026092381 - Multiple vulnerabilities in keepassxc
Published: September 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 vulnerabilities.
1) Integer overflow (CVE-ID: N/A)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an integer overflow in the KDB 1 importer parseGroupTreeState() function when importing a crafted KDB file. A remote attacker can provide a crafted KDB file with a record tree state count that causes an out-of-bounds read to cause a denial of service.
User interaction is required to import the crafted KDB file.
2) Generation of Predictable Numbers or Identifiers (CVE-ID: N/A)
CWE-ID: CWE-340 - Generation of Predictable Numbers or Identifiers
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose SSH agent keys.
The vulnerability exists due to the use of a predictable shared memory name in Pageant SSH agent key sharing when communicating with the Pageant SSH agent on Windows. A local user can pre-create a shared memory handle with the same name to disclose SSH agent keys.
Exploitation requires the attacker to run under the same user account.
3) Out-of-bounds write (CVE-ID: N/A)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in BrowserMessageBuilder browser-integration response encryption when encrypting oversized authorized browser-integration responses. A local user can send a crafted get-logins request to cause a denial of service.
Exploitation requires access to the per-user browser IPC endpoint, a valid database association key, and an unlocked database.
4) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to authorization bypass through a user-controlled key in the KeePassXC-Browser extension when saving login credentials containing references to other entries. A remote attacker can cause a website to save a username or password field as references to other entry data and receive the referenced data when credentials are filled.
User interaction is required to save the login credentials or fill them in; automatic filling can also trigger disclosure.
5) Use-after-free (CVE-ID: CVE-2026-69150)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the KeePass1Reader KDB importer when importing a crafted .kdb file. A local user can trick a victim into importing a crafted .kdb file to cause a denial of service.
User interaction is required to perform the import, and the supplied file must be unlockable using the matching password.
Remediation
Install update from vendor's website.
References
- https://github.com/keepassxreboot/keepassxc/security/advisories/GHSA-rq29-wgrv-xgh4
- https://github.com/keepassxreboot/keepassxc/security/advisories/GHSA-mffq-j98j-wfr2
- https://github.com/keepassxreboot/keepassxc/security/advisories/GHSA-3448-gh8j-3227
- https://github.com/keepassxreboot/keepassxc/commit/61c45ab751863b332d7a88d4c3f1e354cc225abe
- https://github.com/keepassxreboot/keepassxc/security/advisories/GHSA-2vm2-vmc3-vccr
- https://github.com/keepassxreboot/keepassxc/security/advisories/GHSA-4642-49vv-4p43